vendor:
ZoneAlarm
by:
_6mO_HaCk
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: ZoneAlarm
Affected Version From: 3.7.0202
Affected Version To: 4.0 Release
Patch Exists: YES
Related CWE: N/A
CPE: a:zonelabs:zonealarm
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Home Edition, Windows XP Professional
2005
ZoneAlarm Remote DoS Xploit
ZoneAlarm was found vulnerable to a serious vulnerability leading to a remote Denial Of Service condition due to failure to handle udp random packets, if an attacker sends multiple udp packets to multiple ports 0-65000, the machine will hang up until the attacker stop flooding.
Mitigation:
Upgrade to the latest version of ZoneAlarm